Malicious PDF — malware analysis report

Static analysis result for SHA-256 84e67611f48b416f…

MALICIOUS

PDF

21.5 KB Created: 2019-04-30 18:22:51 +01:00 Authoring application: mPDF 5.7
MD5: d7c224d4ab2d2eaa37804b7c6450bd90 SHA-1: f744bf8300b23efa80be5df8467042ad5009332e SHA-256: 84e67611f48b416f7e1817784ce5e215947cc98cdaff58d20269e89bea2812b9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm or SEO poisoning attack. While the specific intent of these links is unclear due to their benign reputation, the sheer volume and the critical heuristic firing suggest a malicious purpose, likely to lure users to compromised or malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099096093096098/The-World-That-Made-New-Orleans-From-Spanish-Silver-to-Congo-Square-by-Ned-Sublette.pdf
    • http://loaminoo.linkpc.net/6091097099096093/Hell-and-Good-Company-The-Spanish-Civil-War-and-the-World-it-Made-by-Richard-Rhodes.pdf
    • http://loaminoo.linkpc.net/7090090099092/Freedom-in-Congo-Square-by-Carole-Boston-Weatherford.pdf
    • http://loaminoo.linkpc.net/6095096098091096/Spies-in-the-Congo-America-s-Atomic-Mission-in-World-War-II-by-Susan-Williams.pdf
    • http://loaminoo.linkpc.net/7093094098097092/New-Orleans-Free-Men-of-Color-Cabinet-Makers-in-the-New-Orleans-Furniture-Trade-1800-1850-by-Margo-Moscou.pdf
    • http://loaminoo.linkpc.net/1093099091099090/The-Spanish-Labyrinth-An-Account-of-the-Social-and-Political-Background-of-the-Spanish-Civil-War-by-Gerald-Brenan.pdf
    • http://loaminoo.linkpc.net/1090096098090099093/English-Grammar-for-Students-of-Spanish-The-Study-Guide-for-Those-Learning-Spanish-by-Emily-Spinelli.pdf
    • http://loaminoo.linkpc.net/2094091092096/Spanish-Fever-Stories-by-the-New-Spanish-Cartoonists-by-Santiago-Garc-a.pdf
    • http://loaminoo.linkpc.net/2097097099092095/The-Square-Peg-The-Square-Peg-1-by-Jane-Davitt.pdf
    • http://loaminoo.linkpc.net/1090095094096099097/Return-of-the-Spanish-Spanish-Bit-Saga-18-by-Don-Coldsmith.pdf
    • http://loaminoo.linkpc.net/4095092096091093/Trail-of-the-Spanish-Bit-Spanish-Bit-Saga-1-by-Don-Coldsmith.pdf
    • http://loaminoo.linkpc.net/6098093090094/This-Broken-Wondrous-World-Man-Made-Boy-2-by-Jon-Skovron.pdf
    • http://loaminoo.linkpc.net/2093099095090096/Oxygen-The-Molecule-That-Made-the-World-by-Nick-Lane.pdf
    • http://loaminoo.linkpc.net/3098094099090093/Wars-that-Made-the-Western-World-by-Timothy-Shutt.pdf
    • http://loaminoo.linkpc.net/4090098097090093/Why-Were-They-Built-Six-Man-Made-Wonders-of-the-World-by-Scott-Hayden.pdf
    • http://loaminoo.linkpc.net/8099091099096094/The-Big-Little-Wedding-in-Carlton-Square-Carlton-Square-1-by-Lilly-Bartlett.pdf
    • http://loaminoo.linkpc.net/1090098093097099099/Accelerated-Spanish-Learn-fluent-Spanish-with-a-proven-accelerated-learning-system-by-Timothy-Moser.pdf
    • http://loaminoo.linkpc.net/4090092094092093/The-World-Slaveholders-Made-Two-Essays-in-Interpretation-by-Eugene-D-Genovese.pdf
    • http://loaminoo.linkpc.net/9091091099097095/Danny-Duck-Tames-the-Lion-Danny-Pato-doma-al-Le-n---Bilingual-Book-in-English-and-Spanish-Study-Spanish-for-Kids-1-by-Colin-Hann.pdf
    • http://loaminoo.linkpc.net/7090099098093096/The-Manifesto-Church-Records-of-the-Church-in-Brattle-Square-Boston-with-Lists-of-Communicants-Baptisms-Marriages-and-Funerals-1699-1872-by-Church-in-Brattle-Square.pdf
    • http://loaminoo.linkpc.net/1093099091099090/The-Spanish-Labyrinth-An-Account-of-the-Social-and-Poli